Type
Campaign
Actors
Pub. date
June 25, 2024
Initial access
Insider threatSupply chain vector
Impact
Supply chain attackDefacement
References
Status
Finalized
Last edited
Oct 28, 2024 12:26 PM
A Chinese company named Funnull acquired the Polyfill domain and GitHub repo, and inserted malware into polyfill.js that redirected users to gambling websites. Further pivoting revealed that Funnull had exposed a CloudFlare API key that linked the company to several CDN providers which were also serving malicious scripts.